InspireICT Posted November 9, 2011 Posted November 9, 2011 A Governor at one of our schools is pushing for us to encrypt the server. We've installed a security cage to the server to fix it to the floor but they want to go a step further. Has anyone actually done this? I imagine rebuilds or repairs to the server would be problematic post-encryption and also that there would be a performance overhead to take into account. Anyone have any other suggestions why this is a bad idea? Thanks in advance
AngryTechnician Posted November 9, 2011 Posted November 9, 2011 I await correction from another member, but I have never encountered a single school that encrypts their onsite servers. There would certainly be a performance hit, and disk maintenance on servers is hard enough due to RAID complexities without throwing encryption in as well. Most encryption systems will require a password to be entered at the server on reboot, with the exception of BitLocker. If the governor is concerned about physical theft, the cage and normal building/server room security should be more than sufficient. If it isn't, you need to think about why the building security is so bad. Who do they think is going to go to that much trouble to steal the server? They are harder to fence than projectors, desktops, and laptops, most of which will be far easier to remove by the car-full before they even get near the server room. I suspect the governor may think that encrypting the server will prevent against remote intrusion, which of course it won't. To be blunt, a governor should not be able to make this sort of operational policy decision without (at the very least) strong evidence to back up the need for it.
Hightower Posted November 9, 2011 Posted November 9, 2011 Personally, I'd be telling the governor where he can take his opinion (and it won't be very bright there either). It is not their role to push for things like this - that's why the school employs you.
pcstru Posted November 9, 2011 Posted November 9, 2011 "THE" server? There will be a performance hit (probably reasonably small and easily absorbed) and additional complexity involved in server backup / restore and credentials management. Encryption could make you more vulnerable to any physical disc corruption, so the risk that you will need to fall back on a backup increases. On the other hand, if the server IS stolen then you perhaps won't be explaining to the ICO why all your data fell into the hand of Daily Mail journalists. I don't think the suggestion is as whacky as others seem to think. If it was suggested at my place of work I'd be delighted that a governor was that interested in the IT infrastructure and I'd try and have a constructive conversation about the pros and cons and what real security benefits we might get for what trade off in operational complexity.
Steve21 Posted November 9, 2011 Posted November 9, 2011 Personally, I'd be telling the governor where he can take his opinion (and it won't be very bright there either). It is not their role to push for things like this - that's why the school employs you. Think that sums it up the best! Steve
AngryTechnician Posted November 9, 2011 Posted November 9, 2011 On the other hand, if the server IS stolen then you perhaps won't be explaining to the ICO why all your data fell into the hand of Daily Mail journalists. I don't think the suggestion is as whacky as others seem to think. I'm less of the opinion that it's a whacky idea in principle, but I think it's definitely the wrong solution for the problem (if a genuine problem even exists). I'd also be delighted to have an interested Governor, but not a paranoid one, which on the face of it seems to be the case here.
pcstru Posted November 9, 2011 Posted November 9, 2011 Who do they think is going to go to that much trouble to steal the server? Someone on the inside? Perhaps poor disposal practices? Maybe just a very very determined and skilled thief? As good as physical security of such important assets tends to be, it's not impossible that they will end up in the wrong hands. And the problem here is that risk is probability AND consequences. We are custodians of some very very sensitive information. If some of that ended up in the wrong hands, the consequences for the data subjects could be very serious. Can you really be too paranoid?
plexer Posted November 9, 2011 Posted November 9, 2011 Ok so anybody using "cloud services" for email etc... should be asking if Microsoft/Google encrypt their servers? Ben
pete Posted November 9, 2011 Posted November 9, 2011 Based on "the server" (singular) and "security cage", I would say the governor has valid security concerns regarding the safety of the data, but his proposed solution will have a hardware and training cost. Is this a "server sat in a classroom / random office" scenario? Having the data stored in a secure manner (locked server room with audited and limited access) meets data protection obligations. Having the data sat unencrypted in a classroom / office where anyone can walk in and touch the server doesn't. If I can poke it with a finger, I can get your data if it isn't encrypted. Talk to the bloke and ask about his concerns.
pete Posted November 9, 2011 Posted November 9, 2011 Ok so anybody using "cloud services" for email etc... should be asking if Microsoft/Google encrypt their servers? Ben I'd guess that the level of physical security between a Google data center and a primary school server (which is what OP sounds like) probably differs. Decently configured encryption (with appropriate precautions and encrypted backups) might be cheaper in the primary school scenario.
pcstru Posted November 9, 2011 Posted November 9, 2011 Ok so anybody using "cloud services" for email etc... should be asking if Microsoft/Google encrypt their servers? Ben Anyone using cloud services should be doing due diligence to satisfy themselves that security and resilience is appropriate for the task. It's one of the problems with "cloud" - how do you actually tick those boxes and provide the evidence to back up that box ticking. I think a lot of people are buying into cloud services and they think that merely writing a cheque somehow guarantees that services providers are behaving responsibly or that simply writing the cheque absolves them of responsibility - "well, I was paying for the service, surely the data WAS safe??".
jamesfed Posted November 9, 2011 Posted November 9, 2011 It sounds like you have pretty good physical security in place already - (better than many others in fact). Using Bitlocker would require a TPM chip in your server (in an ideal situation at least) and this would prevent the need for a password on boot - all the same you would have a small (few percent) drop in disk performance. Backup shouldn't be a problem as your backup system will be backing up the files/folder while the server is running and as such just sees the data a normal. Once you run into any kind of issues with your server (say the OS won't boot and you need to use Windows PE to change something) encrypting it will case MASSIVE problems in getting anything fixed. So as others have said I would speak to your Governor and find out what he is actually looking to achieve - the way I see it SMTs/ect are there to give you problems to solve/ideas to implement but are not there to decide how you do it. One other thing to throw into the mix would be notebook PC encryption - they are a lot more portable than any server and as such present a much greater risk to data loss.
dhicks Posted November 9, 2011 Posted November 9, 2011 A Governor at one of our schools is pushing for us to encrypt the server. If I was going to implement this, I'd go for a block-level encryption system that could provide standard-looking storage volumes for virtual machines running on the server. That way, once you'd booted the server and typed in the passcode or whatever to enable the encrypted volumes, you could start / restart virtual machines as much as you liked.
elsiegee40 Posted November 9, 2011 Posted November 9, 2011 To be blunt, a governor should not be able to make this sort of operational policy decision without (at the very least) strong evidence to back up the need for it. To be blunt, and speaking as a governor, a governor is supposed to be involved in strategic decisions regarding the school not operational ones. It is not the governor's role to recommend encryption of the server. The Governing Body, or a delegated committee, may investigate IT security, but it should not be a governor acting alone. @InspireICT I've attached a part of the "Academies Financial Handbook" regarding the risk register every academy is required to have. The GB puts this together as a strategic document to work out the impact of risks to the academy. There's an explanation of how it works first I suggest that you do a mini version detailing the various risks to your area... You need to think about threats to network and data security at your school and what their impact would be. e.g. "Virus risk/corruption of data risk" might have a likelihood of 3 and an impact of 5 (say)... definitely a "Treat" situation.. with the Control Procedures giving info on your monitoring of anti-virus and backups Other risks you could have are: Failure of 1 or more servers, theft of 1 or more servers, Hacking of 1 school network, Loss/theft of laptop/computer/flash drive It doesn't need to be a massive document. Submit it to the Governing Body via the Clerk and offer to come and talk to the GB so that they ask questions. Hopefully it will manage this governor out of the way. (All communication with the GB should be through the Clerk. Your office staff will tell you who/how) I would suggest you show it to your line manger/HT before you pass it to the clerk. It will at least show that the risks have been considered and are being managed.riskregister.DOCIT risk register sample.DOC 4
GrumbleDook Posted November 14, 2011 Posted November 14, 2011 First and foremost can I just point out that a number of members here are governors or have been governors. From speaking with governors in schools they range from those who have an interest in IT through to people designing infrastructure to run data centres which house MOD systems. Try not to jump to conclusions and definitely do not take the attitude that they should keep out of *your* server room. It is not yours ... it is the school's and governors do have a strong line around the strategy of schools. However, there is a difference between a governor deciding something and a governor working on the strategy for something. Encryption is not out of the realms for consideration, but the DPA principle 7 says all ... Appropriate technical and organisational measures shall be taken against unauthorised or unlawful processing of personal data and against accidental loss or destruction of, or damage to, personal data. If the risk assessment shows that you have taken all reasonable action (security cage, etc) and it is still felt that encryption is needed then you can also make sure you also assess the other things which introduce risk ... insecure buildings (the location of the machine is in an area which it could be snatched by a visitor, the room is on the ground floor with a window next to the street, etc) are sometimes a risk and the school can balance out the cost of an improved server (or servers) which means there would not be a performance hit against the cost of improve building security. An assessment by the school insurers will also help here. If the building is insecure then there are more problems than just the server not being encrypted ... Remember ... it is often not just a single problem when people talk about encryption or security ... and any solution should be part of a whole school strategy / policy.
InspireICT Posted November 14, 2011 Author Posted November 14, 2011 I await correction from another member, but I have never encountered a single school that encrypts their onsite servers. There would certainly be a performance hit, and disk maintenance on servers is hard enough due to RAID complexities without throwing encryption in as well. Most encryption systems will require a password to be entered at the server on reboot, with the exception of BitLocker. If the governor is concerned about physical theft, the cage and normal building/server room security should be more than sufficient. If it isn't, you need to think about why the building security is so bad. Who do they think is going to go to that much trouble to steal the server? They are harder to fence than projectors, desktops, and laptops, most of which will be far easier to remove by the car-full before they even get near the server room. I suspect the governor may think that encrypting the server will prevent against remote intrusion, which of course it won't. To be blunt, a governor should not be able to make this sort of operational policy decision without (at the very least) strong evidence to back up the need for it. In fairness to the governor, the borough have had a couple of primary school servers nicked in the last year which is a really frightening prospect because, as you mentioned you can't easily sell a server down the pub which means they are after the data (there aren't many types of people who would value data from a primary school server - so the over-reaction regarding encryption is understandable). Still doesn't really make it a viable option IMO.
InspireICT Posted November 14, 2011 Author Posted November 14, 2011 Based on "the server" (singular) and "security cage", I would say the governor has valid security concerns regarding the safety of the data, but his proposed solution will have a hardware and training cost. Is this a "server sat in a classroom / random office" scenario? Having the data stored in a secure manner (locked server room with audited and limited access) meets data protection obligations. Having the data sat unencrypted in a classroom / office where anyone can walk in and touch the server doesn't. If I can poke it with a finger, I can get your data if it isn't encrypted. Talk to the bloke and ask about his concerns. Bear in mind that this is a fairly small primary school, a dedicated server room isn't really a possibility. It's kept in an admin office in the centre of the school (ie, as many locked doors between it and the outside world as humanly possible and not too much foot traffic either). We have bolted it to the ground and employ fairly strict password policies.
InspireICT Posted November 14, 2011 Author Posted November 14, 2011 It sounds like you have pretty good physical security in place already - (better than many others in fact). Using Bitlocker would require a TPM chip in your server (in an ideal situation at least) and this would prevent the need for a password on boot - all the same you would have a small (few percent) drop in disk performance. Backup shouldn't be a problem as your backup system will be backing up the files/folder while the server is running and as such just sees the data a normal. Once you run into any kind of issues with your server (say the OS won't boot and you need to use Windows PE to change something) encrypting it will case MASSIVE problems in getting anything fixed. So as others have said I would speak to your Governor and find out what he is actually looking to achieve - the way I see it SMTs/ect are there to give you problems to solve/ideas to implement but are not there to decide how you do it. One other thing to throw into the mix would be notebook PC encryption - they are a lot more portable than any server and as such present a much greater risk to data loss. All of the laptops/notebooks in all of our schools are encrypted as are Flash drives which is where the idea came from I guess but it's a pain in the a**e if anything goes wrong with them, you either have 1 - to decrypt from DOS (approx 16 hours), rebuild/repair and then re-encrypt (between 3 and 6 hours) or 2 - Rebuild from a full disk image (with the chance of losing any local data). Encryption is a good idea for clients generally but it does come with some serious headaches.
p858snake Posted November 14, 2011 Posted November 14, 2011 (edited) In fairness to the governor, the borough have had a couple of primary school servers nicked in the last year which is a really frightening prospect So they should be putting money forward making sure they are all physically secured properly. I'm sorry but a server isn't something that you can pick up with one hand and walk out of a school with... If the people were that determined with the data, They could have just accessed it whilst it was on in the school since they apparently had enough time to steal it. Bear in mind that this is a fairly small primary school, a dedicated server room isn't really a possibility. So there isn't a cleaning closet or storeroom anywhere in the school that they could secure to store it? The one at my primary school was a old toilet room in the admin building. Edited November 14, 2011 by p858snake
Guest hathor Posted November 16, 2011 Posted November 16, 2011 I'd be gearing up for a fight if any governor tried to stick their oar in with such a suggestion. I'd gather as much agreement as possible (such as you are doing here), then submit it to them with the view that it would be bad practice, and nobody else is doing it.
timzim Posted November 16, 2011 Posted November 16, 2011 In fairness to the governor, the borough have had a couple of primary school servers nicked in the last year which is a really frightening prospect because, as you mentioned you can't easily sell a server down the pub which means they are after the data I think this is flawed logic. You may not be able to sell it down the pub but there are plenty of other ways you could raise cash from a nicked server, e.g. sell it on ebay, strip it and sell the parts, etc. Apparently, I hasten to add.
GrumbleDook Posted November 16, 2011 Posted November 16, 2011 I'd be gearing up for a fight if any governor tried to stick their oar in with such a suggestion. I'd gather as much agreement as possible (such as you are doing here), then submit it to them with the view that it would be bad practice, and nobody else is doing it. Sorry ... encryption of servers where appropriate is not bad practice ... it is just that it is unlikely to be the best practice in this case. As soon as you start saying something is bad practice you are on dodgy grounds when it is not. If that governor happens to have previously been a Data Centre designer for MOD then he is likely to know far more than you, but if they are just someone with a strong personal interest but no specialism then it is simply that they don't understand the impact in this specific case. As I've mentioned already ... knocking Governors when you don't know the full background or making generalisations is out of order. I'd love to see you do it to @witch ... that *would* be a sight to see.
dhicks Posted November 16, 2011 Posted November 16, 2011 All of the laptops/notebooks in all of our schools are encrypted as are Flash drives which is where the idea came from I guess but it's a pain in the a**e if anything goes wrong with them Things should be rather simpler server-side, though, especially if you are using virtual machines. The host OS would simply boot from a standard, unencrypted disk and mount the encrypted storage volume that contains your VM images. You would only need to enter a key/passcode when you rebooted the physical host server, which should hopefully be very rarely. It should make no difference to any performance gain / reliability of a RAID array and should hopefully just result in higher processor usage and some file I/O latency as the processor has to encrypt/decrpyt data. You just need to make really sure you don't loose the encryption key. Having multiple copies in safe places would probably be a good idea (including physical printouts in a fireproof safe - typing it in after a disaster might be tedious but better than loosing your data), and you could even put a small, single-function server somewhere around the school (a plug PC, maybe) that could provide the encryption key to the server on boot (so your server could boot and mount the encrypted volume automatically as log as it was on your LAN).
Pottsey Posted November 17, 2011 Posted November 17, 2011 I once encrypted one of the storage drives with photos on but never a whole server. One good reason to not use encryption is anything that cause’s a reboot or power loss will stop the server from powering backup till the encryption password is typed in. This also stops you doing updates via remote access that require reboots.
GrumbleDook Posted November 17, 2011 Posted November 17, 2011 I once encrypted one of the storage drives with photos on but never a whole server. One good reason to not use encryption is anything that cause’s a reboot or power loss will stop the server from powering backup till the encryption password is typed in. This also stops you doing updates via remote access that require reboots. Or you use a lights out KVM or similar offerings.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now